6.8
    Medium

    CVE-2009-2037

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) GLOBALS[SKIN] parameter to index.php and the (2) skin parameter to admin/admin.php.

    Source:YEnH4ckEr
    Published:12 Jun 2009
    7.5
    High

    CVE-2009-2036

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:YEnH4ckEr
    Published:12 Jun 2009
    6
    Medium

    CVE-2009-2034

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.

    Source:Br0ly
    Published:12 Jun 2009
    4.3
    Medium

    CVE-2009-2033

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Br0ly
    Published:12 Jun 2009
    7.5
    High

    CVE-2009-2025

    Last Modified: 23 Apr 2026

    admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.

    Source:ThE g0bL!N
    Published:9 Jun 2009
    5
    Medium

    CVE-2009-2024

    Last Modified: 23 Apr 2026

    Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt.

    Source:ByALBAYX
    Published:9 Jun 2009
    6.8
    Medium

    CVE-2009-2023

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.

    Source:Ams
    Published:9 Jun 2009
    5
    Medium

    CVE-2009-2022

    Last Modified: 23 Apr 2026

    fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb.

    Source:ByALBAYX
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2021

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:OzX
    Published:9 Jun 2009
    4.3
    Medium

    CVE-2009-2020

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter.

    Source:snakespc
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2019

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.

    Source:snakespc
    Published:9 Jun 2009
    6.8
    Medium

    CVE-2009-2018

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.

    Source:snakespc
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2017

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:OzX
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2016

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:OzX
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2015

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Chip d3 bi0s
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2014

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php.

    Source:Chip d3 bi0s
    Published:9 Jun 2009
    7.5
    High

    CVE-2009-2013

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action.

    Source:snakespc
    Published:9 Jun 2009
    9.3
    Critical

    CVE-2009-2011

    Last Modified: 10 Mar 2011

    Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.

    Source:Metasploit
    Published:16 Jun 2009
    6.5
    Medium

    CVE-2009-2010

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.

    Source:YEnH4ckEr
    Published:8 Jun 2009
    7.5
    High

    CVE-2009-2003

    Last Modified: 23 Apr 2026

    Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."

    Source:G4N0K
    Published:8 Jun 2009
    10
    Critical

    CVE-2009-1979

    Last Modified: 7 Mar 2011

    Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.

    Source:Metasploit
    Published:22 Oct 2009
    9
    Critical

    CVE-2009-1978

    Last Modified: 26 Jun 2017

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php.

    Source:ikki
    Published:14 Jul 2009
    10
    Critical

    CVE-2009-1977

    Last Modified: 26 Jun 2017

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.

    Source:ikki
    Published:14 Jul 2009
    6.8
    Medium

    CVE-2009-1975

    Last Modified: 29 Apr 2014

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package.

    Source:Alexandr Polyakov
    Published:14 Jul 2009
    5
    Medium

    CVE-2009-1970

    Last Modified: 1 May 2014

    Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991.

    Source:Dennis Yurichev
    Published:14 Jul 2009
    4.3
    Medium

    CVE-2009-1968

    Last Modified: 29 Apr 2014

    Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.

    Source:Alexandr Polyakov
    Published:14 Jul 2009
    7.5
    High

    CVE-2009-1963

    Last Modified: 1 May 2014

    Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors.

    Source:Dennis Yurichev
    Published:14 Jul 2009
    4.7
    Medium

    CVE-2009-1961

    Last Modified: 6 Sept 2016

    The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

    Source:Miklos Szeredi
    Published:6 Apr 2009
    9.3
    Critical

    CVE-2009-1960

    Last Modified: 23 Apr 2026

    inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

    Source:girex
    Published:6 Jun 2009
    5
    Medium

    CVE-2009-1959

    Last Modified: 26 Apr 2014

    Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

    Source:nemo
    Published:6 Jun 2009
    7.5
    High

    CVE-2009-1955

    Last Modified: 23 Apr 2026

    The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

    Source:kingcope
    Published:1 Jun 2009
    6.8
    Medium

    CVE-2009-1952

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:SirGod
    Published:5 Jun 2009
    4.3
    Medium

    CVE-2009-1951

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.

    Source:SirGod
    Published:5 Jun 2009
    7.5
    High

    CVE-2009-1950

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter.

    Source:Bl@ckbe@rD
    Published:5 Jun 2009
    7.8
    High

    CVE-2009-1949

    Last Modified: 23 Apr 2026

    import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Source:girex
    Published:5 Jun 2009
    5.1
    Medium

    CVE-2009-1948

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read arbitrary recently-modified files via a .. (dot dot) in the GLOBALS[filename] parameter or (2) include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[UTE][__tplCollection][a][file] parameter.

    Source:girex
    Published:5 Jun 2009
    7.5
    High

    CVE-2009-1947

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.

    Source:girex
    Published:5 Jun 2009
    6.8
    Medium

    CVE-2009-1946

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the forumspath parameter.

    Source:Mehmet Ince
    Published:5 Jun 2009
    7.5
    High

    CVE-2009-1945

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

    Source:Bl@ckbe@rD
    Published:5 Jun 2009
    9.3
    Critical

    CVE-2009-1944

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.

    Source:LiquidWorm
    Published:5 Jun 2009
    10
    Critical

    CVE-2009-1943

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.

    Source:Metasploit
    Published:5 Jun 2009
    5
    Medium

    CVE-2009-1941

    Last Modified: 23 Apr 2026

    PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.

    Source:TiGeR-Dz
    Published:5 Jun 2009
    4.3
    Medium

    CVE-2009-1938

    Last Modified: 25 Apr 2014

    Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output and the frontend administrative panel.

    Source:Airton Torres
    Published:5 Jun 2009
    9.8
    Critical

    CVE-2009-1936

    Last Modified: 21 Nov 2016

    _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

    Source:StAkeR
    Published:5 Jun 2009
    10
    Critical

    CVE-2009-1916

    Last Modified: 23 Apr 2026

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.

    Source:SirGod
    Published:4 Jun 2009
    4.3
    Medium

    CVE-2009-1915

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.

    Source:Nine:Situations:Group
    Published:4 Jun 2009
    4.9
    Medium

    CVE-2009-1914

    Last Modified: 21 Apr 2017

    The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers and the request_resource function.

    Source:Mikulas Patocka
    Published:4 Jun 2009
    5.1
    Medium

    CVE-2009-1913

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Source:knxone
    Published:4 Jun 2009
    6.8
    Medium

    CVE-2009-1912

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.

    Source:DNX
    Published:4 Jun 2009
    6.8
    Medium

    CVE-2009-1911

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.

    Source:EgiX
    Published:4 Jun 2009